Back to skill

Security audit

Okx Defi Invest

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent DeFi tooling, but it needs Review because it can guide wallet signing of high-impact on-chain transactions from generated calldata without clearly requiring independent transaction decoding or simulation.

Install only if you are comfortable with an agent helping prepare DeFi transactions. Before signing, verify the wallet address, chain, protocol, token, amount, spender approval, destination contract, fees, and expected asset changes in your wallet or another trusted tool. Avoid signing opaque or unexpected calldata, and treat wallet addresses you provide as financially identifying information.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:211
Finding

Blind Signing and Execution of Remotely Generated Financial Calldata

Content
View full analysis
\ --chain \ --input-data \ --value \ --biz-type defi ``` EVM (XLayer): ```bash onchainos wallet contract-call \ --to \ --chain 196 \ --input-data \ --value \ --biz-type defi ``` Solana: ```bash onchainos wallet contract-call \ --to \ --chain 501 \ --unsigned-tx \ --biz-type defi ``` `contract-call` handles TEE signing and broadcasting internally — no separate broadcast step needed. ``` The corresponding remote response fields are documented in `references/cli-reference.md:249-258`: ```text **Return fields** (`data.dataList` array — execute in order): | Field | Type | Description | |---|---|---| | `dataList[]` | Array | Ordered list of transactions to execute | | `dataList[].callDataType` | String | Operation type: `APPROVE`, `DEPOSIT`, `SWAP,DEPOSIT`, `WITHDRAW`, `WITHDRAW,SWAP` | | `dataList[].from` | String | Sender address (user wallet) | | `dataList[].to` | String | Target contract address | | `dataList[].value` | String | Native token value (e.g. `"0x0"` for no native transfer) | | `dataList[].serializedData` | String | Transaction data: EVM=hex (0x prefix), Solana=base58, Sui=base64 BCS | | `dataList[].originalData` | String | ABI metadata JSON (EVM only) | ``` ### Technical Analysis The skill instructs the Agentic Wallet to sign and broadcast ...[truncated 3298 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata says this skill must remain DApp-agnostic and route any named third-party protocol requests elsewhere, but the CLI reference explicitly supports filtering and discovery by named platforms such as Aave, Compound, Lido, and PancakeSwap. That mismatch can cause the agent to violate routing constraints and execute protocol-specific financial actions in the wrong skill, bypassing intended safety boundaries and policy separation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The examples document position, redeem, and claim workflows for named protocols like Aave and protocol-specific reward flows, despite the manifest stating named third-party protocol interactions should be routed to another skill. This creates an instruction conflict that may lead an agent to expose or perform protocol-specific actions under an incorrect trust model, increasing the chance of unsafe fund movements or policy bypass.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The deposit flow generates executable calldata for approvals, deposits, swaps, borrows, and other irreversible on-chain operations, but the reference does not prominently warn that transactions are final, may incur slippage, approvals can expand token-spending authority, and users can lose funds. In a financial execution skill, omission of these warnings increases the risk of users authorizing harmful or unintended transactions without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The positions and position-detail commands allow querying holdings, rewards, and platform exposure from a wallet address without any privacy notice about linking addresses to financial activity. While blockchain data is public, surfacing it through an agent lowers the barrier for profiling and may lead users to disclose third-party addresses or sensitive portfolio information unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.